Senior Info Security Engineer Analyst - Data Protection Engineer
UnitedHealth Group
- Location
- City of Muntinglupa, Calabarzon
- Work model
- On-Site
- Level
- Senior
Skills
About this role
Optum is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together.
Primary Responsibilities
Manage the deployment of Data Loss Prevention (DLP) solutions across all healthcare clients and contribute to the strategic development of comprehensive insider threat program to streamline consistency Monitor, analyze, and triage alerts from DLP, User and Entity Behavior Analytics (UEBA), CASB, SIEM, and endpoint security systems to identify unauthorized data movement, data exfiltration, policy violations, or abnormal user activity Conduct deep-dive investigations into potential insider threats and data leakage incidents, analyzing telemetry logs, and preserving digital evidence while maintaining strict chain of custody procedures Correlate information across multiple security platforms to identify malicious or negligent activity, and document detailed timelines, root causes, and recommended remediations Partner closely with Cybersecurity, Legal, HR, Compliance, Privacy, and IT teams to identify suspicious behavior, coordinate sensitive investigations, and strengthen data protection controls Maintain, test, and tune DLP policies, detection rules, and alert thresholds to reduce false positives, validate new use cases, and optimize controls across endpoints, email, cloud platforms, and collaboration tools Analyze security telemetry, develop behavioral baselines, and participate in proactive threat-hunting activities to identify recurring behaviors, emerging insider threat risks, and client-specific operational effectiveness Prepare detailed investigation reports, executive summaries, and metrics dashboards for clients; support audits, compliance reviews, and assist in creating security awareness content Use enterprise-approved AI tools to streamline workflows, automate tasks, and drive continuous improvement Evaluate emerging trends to inform solution design and strategic innovation Comply with the terms and conditions of the employment contract, company policies and procedures, and any and all directives (such as, but not limited to, transfer and/or re-assignment to different work locations, change in teams and/or work shifts, policies in regards to flexibility of work benefits and/or work environment, alternative work arrangements, and other decisions that may arise due to the changing business environment). The Company may adopt, vary or rescind these policies and directives in its absolute discretion and without any limitation (implied or otherwise) on its ability to do so Required Qualifications: 2+ years of experience in cybersecurity, information security, or security operations 1+ years of experience administering, configuring, or monitoring Data Loss Prevention (DLP) platforms (such as Symantec DLP, Microsoft Purview, Netskope, etc.) 1+ years of experience analyzing security logs, telemetry, and endpoint activity using SIEM, CASB, or User Behavior Analytics (UBA) tools 1+ years of experience conducting incident investigations, digital forensics, or insider threat analysis, including the collection and preservation of digital evidence Experience utilizing or evaluating automated workflows, AI-driven analytics, or scripting (e.g., Python, PowerShell) to streamline security processes and automate repetitive analyst tasks.
Preferred Qualifications
Professional security certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), GCFE, GCIH, or